Latest CVE Feed
-
5.9
MEDIUMCVE-2024-20060
In da, there is a possible escalation of privilege due to an incorrect status check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08541749; Issue I... Read more
- Published: May. 06, 2024
- Modified: Apr. 30, 2025
-
8.8
HIGHCVE-2024-37765
Machform up to version 19 is affected by an authenticated Blind SQL injection in the user account settings page.... Read more
Affected Products : machform- Published: Jul. 01, 2024
- Modified: Apr. 30, 2025
-
5.4
MEDIUMCVE-2024-37764
MachForm up to version 19 is affected by an authenticated stored cross-site scripting.... Read more
Affected Products : machform- Published: Jul. 01, 2024
- Modified: Apr. 30, 2025
-
5.4
MEDIUMCVE-2024-37763
MachForm up to version 19 is affected by an unauthenticated stored cross-site scripting which affects users with valid sessions whom can view compiled forms results.... Read more
Affected Products : machform- Published: Jul. 01, 2024
- Modified: Apr. 30, 2025
-
9.9
CRITICALCVE-2024-37762
MachForm up to version 21 is affected by an authenticated unrestricted file upload which leads to a remote code execution.... Read more
Affected Products : machform- Published: Jul. 01, 2024
- Modified: Apr. 30, 2025
-
7.5
HIGHCVE-2024-48951
An issue was discovered in Logpoint before 7.5.0. Server-Side Request Forgery (SSRF) on SOAR can be used to leak Logpoint's API Token leading to authentication bypass.... Read more
Affected Products : siem- Published: Nov. 07, 2024
- Modified: Apr. 30, 2025
-
6.4
MEDIUMCVE-2024-48952
An issue was discovered in Logpoint before 7.5.0. SOAR uses a static JWT secret key to generate tokens that allow access to SOAR API endpoints without authentication. This static key vulnerability enables attackers to create custom JWT secret keys for una... Read more
Affected Products : soar- Published: Nov. 07, 2024
- Modified: Apr. 30, 2025
-
7.5
HIGHCVE-2024-48953
An issue was discovered in Logpoint before 7.5.0. Endpoints for creating, editing, or deleting third-party authentication modules lacked proper authorization checks. This allowed unauthenticated users to register their own authentication plugins in Logpoi... Read more
Affected Products : siem- Published: Nov. 07, 2024
- Modified: Apr. 30, 2025
-
6.5
MEDIUMCVE-2025-46228
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bastien Ho Event post allows DOM-Based XSS. This issue affects Event post: from n/a through 5.9.11.... Read more
Affected Products : event_post- Published: Apr. 22, 2025
- Modified: Apr. 30, 2025
- Vuln Type: Cross-Site Scripting
-
5.5
MEDIUMCVE-2021-47172
In the Linux kernel, the following vulnerability has been resolved: iio: adc: ad7124: Fix potential overflow due to non sequential channel numbers Channel numbering must start at 0 and then not have any holes, or it is possible to overflow the available... Read more
Affected Products : linux_kernel- Published: Mar. 25, 2024
- Modified: Apr. 30, 2025
-
6.3
MEDIUMCVE-2021-47189
In the Linux kernel, the following vulnerability has been resolved: btrfs: fix memory ordering between normal and ordered work functions Ordered work functions aren't guaranteed to be handled by the same thread which executed the normal work functions. ... Read more
Affected Products : linux_kernel- Published: Apr. 10, 2024
- Modified: Apr. 30, 2025
-
5.9
MEDIUMCVE-2025-46229
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Israpil Textmetrics allows Stored XSS. This issue affects Textmetrics: from n/a through 3.6.2.... Read more
Affected Products : textmetrics- Published: Apr. 22, 2025
- Modified: Apr. 30, 2025
- Vuln Type: Cross-Site Scripting
-
5.7
MEDIUMCVE-2024-51004
Netgear R8500 v1.0.2.160 and R7000P v1.3.3.154 were discovered to multiple stack overflow vulnerabilities in the component usb_device.cgi via the cifs_user, read_access, and write_access parameters. These vulnerabilities allow attackers to cause a Denial ... Read more
- Published: Nov. 05, 2024
- Modified: Apr. 30, 2025
-
5.7
MEDIUMCVE-2024-51002
Netgear R8500 v1.0.2.160, XR300 v1.0.3.78, R7000P v1.3.3.154, and R6400 v2 1.0.4.128 were discovered to contain a stack overflow via the l2tp_user_ip parameter at l2tp.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via a craft... Read more
Affected Products : r7000p_firmware r6400_firmware r6400v2_firmware xr300_firmware r8500_firmware r7000p r8500 xr300 r6400v2- Published: Nov. 05, 2024
- Modified: Apr. 30, 2025
-
8.8
HIGHCVE-2025-46231
Cross-Site Request Forgery (CSRF) vulnerability in SERVIT Software Solutions affiliate-toolkit allows Cross Site Request Forgery. This issue affects affiliate-toolkit: from n/a through 3.7.3.... Read more
Affected Products : affiliate-toolkit- Published: Apr. 22, 2025
- Modified: Apr. 30, 2025
- Vuln Type: Cross-Site Request Forgery
-
8.8
HIGHCVE-2025-46232
Missing Authorization vulnerability in alttextai Download Alt Text AI allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Download Alt Text AI: from n/a through 1.9.93.... Read more
Affected Products : alt_text_ai- Published: Apr. 22, 2025
- Modified: Apr. 30, 2025
- Vuln Type: Authorization
-
5.3
MEDIUMCVE-2021-47192
In the Linux kernel, the following vulnerability has been resolved: scsi: core: sysfs: Fix hang when device state is set via sysfs This fixes a regression added with: commit f0f82e2476f6 ("scsi: core: Fix capacity set to zero after offlinining device")... Read more
Affected Products : linux_kernel- Published: Apr. 10, 2024
- Modified: Apr. 30, 2025
-
7.1
HIGHCVE-2021-47262
In the Linux kernel, the following vulnerability has been resolved: KVM: x86: Ensure liveliness of nested VM-Enter fail tracepoint message Use the __string() machinery provided by the tracing subystem to make a copy of the string literals consumed by th... Read more
Affected Products : linux_kernel- Published: May. 21, 2024
- Modified: Apr. 30, 2025
-
7.8
HIGHCVE-2024-53920
In elisp-mode.el in GNU Emacs before 30.1, a user who chooses to invoke elisp-completion-at-point (for code completion) on untrusted Emacs Lisp source code can trigger unsafe Lisp macro expansion that allows attackers to execute arbitrary code. (This unsa... Read more
Affected Products : emacs- Published: Nov. 27, 2024
- Modified: Apr. 30, 2025
-
6.5
MEDIUMCVE-2025-46233
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Sirv CDN and Image Hosting Sirv allows Stored XSS. This issue affects Sirv: from n/a through 7.5.3.... Read more
Affected Products : sirv- Published: Apr. 22, 2025
- Modified: Apr. 30, 2025
- Vuln Type: Cross-Site Scripting